Entradas

Reflection about Security and Privacy course

My experience with this course was a good one. I learned more theory about security and privacy than hands on learning, which  isn't a bad thing but i would've preferred some practice sessions with the Wizeline team on topics that could've helped us during the development of our project. My team and i had to really do some research on how to do 2FA with the technologies that we were using, we didn't have a guide line to get ourselves started. But as usual we managed to get it done. I think that including the Wizeline Security team really gave the course a plus. Taking this course really opened my eyes towards the Security aspect of software, because being a good programmer is so much more than just writing good code. It's about allowing yourself to explore every different angle of programming. The goal is to become a professional a multidimensional programmer and that's also my goal.  I believe that the goal of this course was to comprehend the impo...

Security Standards and Certifications

Some of the top security certifications: CEH: Certified Ethical Hacker CISM: Certified Information Security Manager CompTIA Security+ CISSP: Certified Information Systems Security Professional GSEC: SANS GIAC Security Essentials References: Tittel, E. (2018). Best Information Security Certifications 2018. Business News Daily Contributing Writers. Retrieved from: https://www.businessnewsdaily.com/10708-information-security-certifications.html

Network and Wireless Security

"Wireless networks are inherently insecure" (Lawrence, 2018). "Wireless network security primarily protects a wireless network from unauthorized and malicious access attempts". (Technopedia, 2018) There are 3 indispensable wireless security protocols: WEP, WPA, and WPA2, each with their own strengths, and weaknesses. In addition to preventing uninvited guests from connecting to your wireless network, wireless security protocols encrypt your private data as it is being transmitted over the airwaves. To further understand these protocols we need to define each one of them: Wired Equivalent Privacy (WEP): The original encryption protocol developed for wireless networks. As its name implies, WEP was designed to provide the same level of security as wired networks. However, WEP has many well-known security flaws, is difficult to configure, and is easily broken. Wi-Fi Protected Access (WPA): Introduced as an interim security enhancement over WEP while the 802.11i wire...

Security Countermeasures and Denial of Service

" Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks impact system availability by flooding the target system with traffic or requests or by exploiting a system or software flaw" (PCcare, 2018). What happens during a DoS attack , is that a single attacker directs an attack against a single target, sending packets directly to the target. It basically targets the network bandwidth or connectivity. There are many common forms of DoS attacks , for example: Smurf Fraggle Ping flood Ping-of-death Syn Flood Land Teardrop DNS poisoning Banana Attack Negative Acknowledgement (NACK) Deuthentication (Deauth) One of the most knowledgeable and used is Spam . It consists of sending unwanted e-mail messages to users. It's considered a from of DoS because: It consumes bandwidth that is used by legitimate traffic.  It can fill a mailbox or hard disk and result in legitimate e-mail being rejected.  Spam is often distributed by hijacking misconfigured...

Unintentional Security Issues and Malware

There're a great deal of accidental security issues but i'm focusing on how the human factor intercedes with data security and integrity. Up to 28% of Enterprise Data Security Incidents Come from Inside While hackers are growing more and more sophisticated, much of the threat of organizations actually comes from inside. That isn’t to say that any of the employees has malicious intent, though it’s possible, but they may be poorly trained, or the enterprise data security policies may be poorly enforced. All of these leading to Unintentional Security Issues. 32% of companies surveyed said that insider events were “more costly or damaging” than similar attacks coming from the outside. But in order to toughen up your security stance and protect yourself from the enemy within, it’s important to know how your employees may be compromising your digital security. 2014 was a rough year for enterprise data security, if the high profile breaches of Sony, JPMorgan an...

Operating System Security (Linux Focus)

The process of ensuring OS integrity, confidentiality and availability "OS security refers to specified steps or measures used to protect the OS from threats, viruses, worms, malware or remote hacker intrusions. OS security encompasses all preventive-control techniques, which safeguard any computer assets capable of being stolen, edited or deleted if OS security is compromised" (Technopedia, 2018) Why is is Linux is the most secure operating system? Linux has the potential to be the most secure OS if the users is experienced or acquainted with security protocols, terms and technology. Even though Linux is open source people might think that it's the least secure OS, but in fact it's an important reason why Linux is so secure because Anyone can review code and make sure there are no bugs or back doors. Linux is reviewed by the tech community, which lends itself to security: "By having that much oversight, there are fewer vulnerabilities, bugs a...

Data Integrity and Management

Imagen
Data integrity has become a serious issue over the past few years and therefore is a core focus of many enterprises. What is Data Integrity? "Data integrity refers to the fact that data must be reliable and accurate over its entire lifecycle " (Finestone, 2018), meaning that the data lifecycle provides a high level overview of the stages involved in successful management and preservation of data for use and reuse. Data integrity and data security go hand in hand, even though they’re separate concepts. Uncorrupted data (integrity) is considered to be whole and then stay unchanged relative to that complete state. Maintaining or keeping data consistent throughout its lifecycle is a matter of protecting it (security) so that it’s reliable. And data that’s reliable is simply able to meet certain standards, with which compliance is necessary. Data is expected to be (Finestone, 2018): Attributable - Data should clearly demonstrate who observed and recorded it, wh...

Authentication, Access Control and Security Policies

Imagen
Authentication, Access Control and Security Policies , these three concepts define modern-day protection in the world of technology. But first let's define each one of them. What is Authentication ? "The process of determining whether someone or something is, in fact, who or what it declares itself to be" (Rosencrance, 2018). How authentication is used: Authentication technology provides access control for systems by checking to see if a user's credentials match the credentials in a database of authorized users or in a data authentication server. Generally, a user has to choose a username or user ID and provide a valid password to begin using a system. User authentication authorizes human-to-machine interactions in operating systems and applications, as well as both wired and wireless networks to enable access to networked and internet-connected systems, applications and resources. Authentication factors: Knowledge factor: "Something you kno...

Ethics and Legal Responsibility

Imagen
"Legal ethics is a term used to describe a code of conduct governing proper professional behavior, which establishes the nature of obligations owed to individuals and to society" (FindLaw, 2018).  The fact that people or institutions have a right to do something doesn't imply that they should do it. The law sets out what people are free to do, regardless of the effect that those actions have on others. For example, in Mexico The Federal Civil Code establishes 14 years of age as the minimum age for girls to marry and 16 years of age for boys. It is legally posible for mature adults to marry young girls but ethically it's not right because these are harmful practices that not only do they seriously affect the life, health, education and integrity of girls, but also violate the human rights of every little girl who has the misfortune of being a victim of this awful practice. Having the legal right to do something is not the same as fulfilling one's ethical ...

Cryptography

Imagen
The fact is there's no such thing as a perfectly, 100& secure computer system. There will always be bugs and security experts know that. So that were System Architects employ a strategy called defense in depth, which uses many layers of varying security mechanisms to frustrate attackers. A common reference to this is looking back at medieval times where you have a to keep safe the King of a land and it's castle. Attackers or enemies need to beat or dodge various obstacles in order to gain access to the castle and conquer it, but int this context we're talking about the most common forms of computer security called   Cryptography. Whats is Cryptography? The word comes from the roots 'crypto' + 'graphy' which roughly translates to  = Secret Writing. In order to make information secret you use Cipher, an algorithm that converts plain text into CipherText. Whats is Encryption? T...

Internet Security and Privacy

Imagen
Private data and civil liberties are at risk nowadays there isn't enough transparency so that people are aware of how their data is being shaped and circulated. Most users don't have technical expertise and leveraging internet power requires those set of skills and people with those with enough abilities always stay ahead of institutional power or controls. That is why cyber crimes are still present, even as the government power gets better. This is why whistleblowers can cause so much damage. Institutional controls let companies use data but they put very strict conditions to prove that they are not misusing that data. Privacy is about consumer trust, it's about online user trust.   In the digital age, we typically apply the concept of data privacy to critical personal information, also known as personally identifiable information (PII) and personal health information (PHI). But why is privacy important? Privacy is a limit on government power, as wel...

TC2027 Week 1 Computer and Information Security

Imagen
Setting up the Blog for Computer and Information Security Course

Patrol Unity 101

Imagen
Creating a patrolling movement in a Game object can be hard but by creating waypoints that specify the path to be followed by your object it can be an easier task. https://cocalp.wixsite.com/unity101

User interface design and software verification and validation

Imagen
User interface design and software verification and validation User interface design  is the  design  of  user interfaces  for machines and software with the focus on maximizing usability and the  user  experience.  focuses on anticipating what users might need to do and ensuring that the interface has elements that are easy to access, understand, and use to facilitate those actions. UI brings together concepts from  interaction design ,  visual design , and  information architecture . They are 19 principles of  User Interface Design: Clarity is job  Interfaces exist to enable interaction Conserve attention at all costs Keep users in control Direct manipulation is best One primary action per screen Keep secondary actions secondary Provide a natural next step Appearance follows behavior Consistency matters Strong visual hierarchies work best Smart organization reduces cognitive load Highlight, don't...

TC1019 Course Review

TC1019 Review Decidi hacer este post en español para explayarme más y dar a entender mejor mi punto de vista sobre el curso de  Fundamentals of Software Engineering que tome con el profesor Ken Bauer . Temas : En el curso en total son 20 temas que vimos a lo largo del semestre, mas o menos por que también nos dejaba leer algunos artículos que tenían mucha información muy interesante y sentías como si fuera otro  mastery topic . Los temas son muy variados, lo cual es muy importante por que si te enfado uno o no te intereso tanto ese tema puedes investigar otro tema de los  mastery's , ya que no tienen un orden particular. En lo personal los temas con los que más di click o me interesaron bastante fueron open source software, XP,  software design y  software architecture; creo que se nota por que fueron los blogs más enfocados en mi punto de vista y no tanto investigación que encontré. Abolish Grading: Este...

Software implementation and Software maintenance

Imagen
Software implementation and  Software maintenance Software implementation can represent a very complex task for big companies. The incorporation of a new tool may take several phases; companies need to consider the costs in money and time for the change to represent gains on their finance. The changes are so complex that some companies operate over legacy software that was released decades ago and offer no support. "Implementation is the carrying out, execution, or practice of a plan, a method, or any design, idea, model, specification, standard or policy for doing something. It's the action that must follow any preliminary thinking in order for something to actually happen "(Rouse, 2014). Software implementation surrounds all the post-sale processes involved in something operating properly in its environment. It includes analyzing requirements, installation, configuration, customization, running, testing, systems integrations, user training, delivery and...
Imagen
The waterfall method Waterfall  is a linear approach to software development, t his means that as each of the eight stages (conception, initiation, analysis, design, construction, testing, implementation, and maintenance) are completed, the developers move on to the next step (Base 36, 2016). Waterfall vs Agile: Benefits of the waterfall method: Once a step has been completed, developers can’t go back to a previous stage and make changes and get things done a lot faster. It relies heavily on initial requirements. However, if these requirements are faulty in any manner, the project is doomed. If a requirement error is found, or a change needs to be made, the project has to start from the beginning with all new code. The whole product is only tested at the end. If bugs are written early, but discovered late, their existence may have affected how other code was written. Additionally, the temptation to delay thorough testing is often very high, as these delays a...
Imagen
API 101 A pplication  p rogram  i nterface  ( API ) is a set of  routines ,  protocols , and tools for building  software applications . An API specifies how software components should interact and APIs are used when programming graphical user interface ( GUI ) components. A good API makes it easier to develop a  program  by providing all the building blocks. A  programmer  then puts the blocks together" (webopedia, 2016). Application Programming Interfaces   allows applications to talk to other applications. For example:  M obile devices all use APIs to connect our mobile app to Facebook. YouTube users  consume  videos using the universal embeddable video player (like Vimeo) allowing Youtube videos to be embedded on any website around the web, all driven by APIs. Sources & Links: http://www.webopedia.com/TERM/A/API.html http://rightleftcommunication.com/wp-content/uploads/2015/05/api-integra...
Imagen
Software testing – what kinds of testing? "Software testing is a process of executing a program or application with the intent of finding the  software bugs ". In other words it can also be called as a  process of validating and verifying  that a software program or application or product: Meets the business and technical requirements that guided it’s design and development Works as expected Can be implemented with the same characteristic. Why is it necessary ? is necessary because we can make mistakes that could cause the company a lot of money or completely crash our software and affect other people using it. We need to check  everything we make because things can always go wrong. Other important reasons we need software testing: It points out the flaws in the software that were made during the development phases. It ensures the customer’s reliability and their satisfaction with the program. It ...

Software requirements elicitation and specification Functional and non functional requirements

Imagen
Software requirements elicitation and specification Functional and non functional requirements Requirements Elicitation is the process to find out the requirements for an intended software system by communicating with client, end users, system users and others who have a stake in the software system development. Requirement Elicitation Process: Why is requirement elicitation necessary? Knowing what problems to be solved and recognizing system boundaries. Identifying who are the stakeholders. Recognizing the goal of system is the target to be achieved. Software Requirement Specification is a document created by system analyst after the requirements are collected from various stakeholders. Defines how the intended software will interact with hardware, external interfaces, speed of operation.   The functional requirement is  describing the behavior of the system  as it relates to the system's functionality. F unct...